Agent skill

Crypto Engineer

by FerroxLabs in FerroxLabs/wayland

Cryptography implementation expertise covering symmetric vs asymmetric encryption, password hashing (bcrypt, argon2), digital signatures, key management, TLS configuration, secure random generation…

Apache-2.0Auto-check passedSecurity

Install Crypto Engineer

skills CLI
$ npx skills add FerroxLabs/wayland --skill crypto-engineer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install FerroxLabs/wayland crypto-engineer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/security/crypto-engineer .claude/skills/crypto-engineer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
crypto-engineer
GitHub stars
608
Token cost
~4k tokens
SKILL.md length
486 words
Files
1
Skills in repo
1,194
Repo updated
First seen
Licence
Apache-2.0

At a glance

Cryptography implementation expertise covering symmetric vs asymmetric encryption, password hashing (bcrypt, argon2), digital signatures, key management, TLS configuration, secure random generation…

  • The user asks about crypto engineer
  • SKILL.md covers Overview, Symmetric vs Asymmetric…, Password Hashing and Digital Signatures, plus 6 more sections
  • Calls openssl
  • Crypto engineer best practices

What it does

Crypto Engineer is an agent skill from FerroxLabs/wayland. Cryptography implementation expertise covering symmetric vs asymmetric encryption, password hashing (bcrypt, argon2), digital signatures, key management, TLS configuration, secure random generation, common cryptographic pitfalls, and practical usage of libsodium and OpenSSL for building secure systems. Use when the user asks about crypto engineer, crypto engineer best practices, or needs guidance on crypto engineer implementation. Do NOT use when the user needs a different specialized skill or is asking about an…

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Cryptography. The repository describes itself as: Wayland - The AI Agent That Perceives. Reasons. Acts. Evolves. The licence is Apache-2.0.

When your agent uses it

  • The user asks about crypto engineer
  • Crypto engineer best practices
  • Needs guidance on crypto engineer implementation
  • The user needs a different specialized skill

Example prompts

  • “/crypto-engineer”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 4c030c7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Crypto Engineer loads about 4k tokens when it runs. Until then it costs about 141 tokens; SKILL.md has 486 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~141
When it runs · the whole SKILL.md, loaded when a task matches
~4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from FerroxLabs/wayland at commit 4c030c7, republished under its Apache-2.0 licence (© FerroxLabs). 486 words, ~4,011 tokens.

Download SKILL.mdSave it as .claude/skills/crypto-engineer/SKILL.md (or your agent's skills folder).
name
crypto-engineer
description
Cryptography implementation expertise covering symmetric vs asymmetric encryption, password hashing (bcrypt, argon2), digital signatures, key management, TLS configuration, secure random generation, common cryptographic pitfalls, and practical usage of libsodium and OpenSSL for building secure systems. Use when the user asks about crypto engineer, crypto engineer best practices, or needs guidance on crypto engineer implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
license
Apache-2.0
metadata.author
foundry-skills
metadata.version
1.0.0
metadata.tags
security guide best-practices
metadata.category
security
metadata.subcategory
application-security
metadata.disclaimer
none
metadata.difficulty
intermediate

Cryptography Engineer

Overview

Cryptography is the foundation of secure systems. This skill covers the practical implementation of cryptographic operations -- not the mathematical theory, but the engineering decisions that determine whether your encryption actually protects data. The cardinal rule of cryptography is: never implement your own cryptographic primitives. Use well-vetted libraries and follow established patterns.

Symmetric vs Asymmetric Encryption

Decision Matrix
PropertySymmetricAsymmetric
SpeedFast (100x+)Slow
Key distributionRequires shared secretPublic key can be shared
Key size128-256 bits2048-4096 bits (RSA), 256 bits (ECC)
Use caseBulk data encryptionKey exchange, digital signatures
ExamplesAES-GCM, ChaCha20-Poly1305RSA, ECDSA, Ed25519, X25519
Symmetric Encryption (AES-GCM)
python
# AES-256-GCM: authenticated encryption (confidentiality + integrity)
from cryptography.hazmat.primitives.ciphers.aead import AESGCM
import os

def encrypt_aes_gcm(plaintext: bytes, key: bytes) -> bytes:
    """
    Encrypt with AES-256-GCM.
    Returns: nonce (12 bytes) + ciphertext + tag (16 bytes)
    """
    if len(key) != 32:
        raise ValueError("Key must be 32 bytes for AES-256")

    nonce = os.urandom(12)  # 96-bit nonce, MUST be unique per key
    aesgcm = AESGCM(key)
    # ... (condensed) ...
def encrypt_with_aad(plaintext: bytes, key: bytes, aad: bytes) -> bytes:
    nonce = os.urandom(12)
    aesgcm = AESGCM(key)
    ciphertext = aesgcm.encrypt(nonce, plaintext, associated_data=aad)
    return nonce + ciphertext
ChaCha20-Poly1305 (Alternative to AES-GCM)
python
# Preferred on platforms without AES hardware acceleration (ARM, mobile)
from cryptography.hazmat.primitives.ciphers.aead import ChaCha20Poly1305
import os

def encrypt_chacha(plaintext: bytes, key: bytes) -> bytes:
    """Encrypt with ChaCha20-Poly1305."""
    nonce = os.urandom(12)
    chacha = ChaCha20Poly1305(key)
    ciphertext = chacha.encrypt(nonce, plaintext, associated_data=None)
    return nonce + ciphertext

# Key generation
key = ChaCha20Poly1305.generate_key()
Asymmetric Encryption (RSA-OAEP)
python
from cryptography.hazmat.primitives.asymmetric import rsa, padding
from cryptography.hazmat.primitives import hashes, serialization

# Key pair generation
private_key = rsa.generate_private_key(
    public_exponent=65537,
    key_size=4096,  # Minimum 2048, prefer 4096
)
public_key = private_key.public_key()

# Encrypt with public key (anyone can encrypt)
def rsa_encrypt(plaintext: bytes, public_key) -> bytes:
    return public_key.encrypt(
        plaintext,
        # ... (condensed) ...

public_pem = public_key.public_bytes(
    encoding=serialization.Encoding.PEM,
    format=serialization.PublicFormat.SubjectPublicKeyInfo,
)

Password Hashing

Algorithm Selection
AlgorithmRecommendedTunableNotes
Argon2idBest choiceTime, memory, parallelismWinner of Password Hashing Competition
bcryptGoodCost factorWidely deployed, 72-byte limit
scryptGoodCPU, memory, parallelismUsed in cryptocurrency
PBKDF2AcceptableIterationsNIST approved, weakest of the four
MD5/SHA1/SHA256NEVERN/ANot password hashing functions
python
from argon2 import PasswordHasher, Type
from argon2.exceptions import VerifyMismatchError

# Production configuration
ph = PasswordHasher(
    time_cost=3,          # Number of iterations
    memory_cost=65536,    # 64 MB memory usage
    parallelism=4,        # 4 threads
    hash_len=32,          # Output hash length
    salt_len=16,          # Salt length
    type=Type.ID,         # Argon2id (hybrid, recommended)
)

# Hash password
# ... (condensed) ...
    return ph.check_needs_rehash(stored_hash)

# Tuning: target 0.5-1.0 seconds per hash
# Increase memory_cost first (makes GPU attacks expensive)
# Then increase time_cost if more latency is acceptable
bcrypt
python
import bcrypt

# Hash with bcrypt (work factor 12 = ~250ms on modern hardware)
def hash_password_bcrypt(password: str) -> str:
    salt = bcrypt.gensalt(rounds=12)
    hashed = bcrypt.hashpw(password.encode('utf-8'), salt)
    return hashed.decode('utf-8')

# Verify
def verify_password_bcrypt(stored_hash: str, password: str) -> bool:
    return bcrypt.checkpw(
        password.encode('utf-8'),
        stored_hash.encode('utf-8')
    )
# ... (condensed) ...
    # Pre-hash to handle passwords > 72 bytes
    pre_hash = base64.b64encode(
        hashlib.sha256(password.encode('utf-8')).digest()
    )
    return bcrypt.hashpw(pre_hash, bcrypt.gensalt(rounds=12)).decode('utf-8')

Digital Signatures

python
from cryptography.hazmat.primitives.asymmetric.ed25519 import Ed25519PrivateKey
from cryptography.hazmat.primitives import serialization

# Generate signing key
private_key = Ed25519PrivateKey.generate()
public_key = private_key.public_key()

# Sign
def sign_message(message: bytes, private_key) -> bytes:
    return private_key.sign(message)

# Verify
def verify_signature(message: bytes, signature: bytes, public_key) -> bool:
    try:
        # ... (condensed) ...
# - Fast (10x faster than RSA)
# - Small signatures (64 bytes vs 256+ for RSA)
# - Small keys (32 bytes vs 256+ for RSA)
# - Deterministic (same message = same signature, no random failures)
# - Resistant to many implementation pitfalls
RSA Signatures (PSS padding)
python
from cryptography.hazmat.primitives.asymmetric import rsa, padding, utils
from cryptography.hazmat.primitives import hashes

# Sign with RSA-PSS (preferred over PKCS1v15 for new code)
def rsa_sign(message: bytes, private_key) -> bytes:
    return private_key.sign(
        message,
        padding.PSS(
            mgf=padding.MGF1(hashes.SHA256()),
            salt_length=padding.PSS.MAX_LENGTH
        ),
        hashes.SHA256()
    )

# ... (condensed) ...
            hashes.SHA256()
        )
        return True
    except Exception:
        return False

Key Management

Key Hierarchy
Master Key (KEK - Key Encryption Key)
  |
  +-- Data Encryption Key (DEK) for database encryption
  |
  +-- Data Encryption Key (DEK) for file encryption
  |
  +-- Data Encryption Key (DEK) for API token encryption

The master key encrypts all DEKs.
DEKs encrypt actual data.
This allows key rotation without re-encrypting all data.
Envelope Encryption Pattern
python
import os
from cryptography.hazmat.primitives.ciphers.aead import AESGCM

class EnvelopeEncryption:
    """
    Envelope encryption: encrypt data with a DEK,
    encrypt the DEK with a KEK (master key).
    """

    def __init__(self, master_key: bytes):
        self.master_key = master_key  # From KMS, HSM, or secure config

    def encrypt(self, plaintext: bytes) -> dict:
        # Generate random DEK for this encryption
        # ... (condensed) ...
        data_nonce = envelope['encrypted_data'][:12]
        data_cipher = AESGCM(dek)
        return data_cipher.decrypt(
            data_nonce, envelope['encrypted_data'][12:], None
        )
Key Rotation
python
class KeyRotationManager:
    """Manage key rotation without re-encrypting all data."""

    def __init__(self, key_store):
        self.key_store = key_store

    def rotate_master_key(self):
        """Generate new master key, keep old for decryption."""
        new_key = AESGCM.generate_key(bit_length=256)
        new_version = self.key_store.get_current_version() + 1
        self.key_store.store_key(new_version, new_key)
        self.key_store.set_current_version(new_version)
        # Old keys remain available for decryption
        # New encryptions use new key
# ... (condensed) ...
    def decrypt(self, envelope: dict) -> bytes:
        key_version = envelope['key_version']
        key = self.key_store.get_key(key_version)
        decryptor = EnvelopeEncryption(key)
        return decryptor.decrypt(envelope)

TLS Configuration

Server Configuration (Nginx)
nginx
# Modern TLS configuration (TLS 1.3 only)
ssl_protocols TLSv1.3;
ssl_prefer_server_ciphers off;

# Intermediate TLS configuration (TLS 1.2 + 1.3)
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES256-GCM-SHA384;
ssl_prefer_server_ciphers off;

# OCSP stapling
ssl_stapling on;
ssl_stapling_verify on;

# Session settings
# ... (condensed) ...
ssl_certificate [system-path]
ssl_certificate_key [system-path]

# DH parameters (generate with: openssl dhparam -out dhparam.pem 4096)
ssl_dhparam [system-path]
TLS Testing
shell
# Test TLS configuration
# SSLLabs (web): [reference URL]
# testssl.shell-cmd (CLI):
testssl.shell-cmd [reference URL]

# OpenSSL client testing
openssl s_client -connect example.com:443 -tls1_3
openssl s_client -connect example.com:443 -tls1_2

# Check certificate details
openssl s_client -connect example.com:443 </dev/null 2> output_file | \
    openssl x509 -noout -text

# Verify certificate chain
openssl verify -CAfile ca-bundle.crt certificate.pem

Secure Random Generation

python
import os
import secrets

# CORRECT: Cryptographically secure random
token = secrets.token_hex(32)            # 64 hex chars
token = secrets.token_urlsafe(32)        # 43 URL-safe chars
random_bytes = os.urandom(32)            # 32 random bytes
random_int = secrets.randbelow(1000000)  # Random int [0, 1000000)

# WRONG: Not cryptographically secure (predictable)
import random
token = random.randint(0, 999999)  # NEVER for security purposes
# random.Random uses Mersenne Twister - predictable after 624 outputs

# ... (condensed) ...
    return f"{prefix}_{random_part}"

# Constant-time comparison (prevents timing attacks)
def safe_compare(a: str, b: str) -> bool:
    return secrets.compare_digest(a.encode(), b.encode())

Common Cryptographic Pitfalls

Pitfall 1: ECB Mode
ECB (Electronic Codebook) encrypts each block independently.
Identical plaintext blocks produce identical ciphertext blocks.
This reveals patterns in the data.

NEVER use ECB mode. Use GCM or CTR with authentication.
Pitfall 2: Unauthenticated Encryption
AES-CBC without HMAC allows bit-flipping attacks.
An attacker can modify ciphertext to change the decrypted plaintext
in predictable ways without knowing the key.

ALWAYS use authenticated encryption:
  - AES-GCM (recommended)
  - ChaCha20-Poly1305 (recommended)
  - AES-CBC + HMAC-SHA256 (encrypt-then-MAC, acceptable)
Pitfall 3: Nonce Reuse
Reusing a nonce with the same key in AES-GCM or ChaCha20-Poly1305
completely breaks confidentiality and authenticity.

Solutions:
  - Use random 96-bit nonce (safe for ~2^32 encryptions per key)
  - Use a counter-based nonce (safe for 2^96 encryptions)
  - Rotate keys before nonce space exhaustion
  - Use AES-GCM-SIV (nonce-misuse resistant) if nonce uniqueness
    cannot be guaranteed
Pitfall 4: Timing Attacks
python
# VULNERABLE: String comparison leaks length info
def check_token(provided, expected):
    return provided == expected  # Short-circuits on first mismatch

# FIXED: Constant-time comparison
import hmac
def check_token_safe(provided, expected):
    return hmac.compare_digest(
        provided.encode('utf-8'),
        expected.encode('utf-8')
    )
Pitfall 5: Insufficient Key Derivation

Libsodium Usage

python
# Libsodium via PyNaCl - higher-level, harder to misuse
from nacl.public import PrivateKey, PublicKey, Box
from nacl.secret import SecretBox
from nacl.signing import SigningKey
from nacl.utils import random

# Symmetric encryption (SecretBox = XSalsa20-Poly1305)
key = random(SecretBox.KEY_SIZE)  # 32 bytes
box = SecretBox(key)
encrypted = box.encrypt(b"secret message")  # nonce auto-generated
decrypted = box.decrypt(encrypted)

# Asymmetric encryption (Box = X25519 + XSalsa20-Poly1305)
alice_key = PrivateKey.generate()
# ... (condensed) ...
# Digital signatures (Ed25519)
signing_key = SigningKey.generate()
verify_key = signing_key.verify_key
signed = signing_key.sign(b"important message")
verify_key.verify(signed)  # Raises BadSignatureError if tampered

Algorithm Selection Quick Reference

PurposeRecommendedAcceptableNever Use
Symmetric encryptionAES-256-GCM, ChaCha20-Poly1305AES-256-CBC + HMACAES-ECB, DES, 3DES, RC4
Password hashingArgon2idbcrypt, scryptMD5, SHA-1, SHA-256 (raw)
Digital signaturesEd25519ECDSA (P-256), RSA-PSS (4096)RSA-PKCS1v15, DSA
Key exchangeX25519ECDH (P-256)RSA key transport < 2048
Hashing (non-password)SHA-256, SHA-3, BLAKE2SHA-512MD5, SHA-1
MACHMAC-SHA256Poly1305HMAC-MD5
Random generationos.urandom, secrets/dev/urandomrandom.Random, Math.random
Show full SKILL.md (198 more words)Show less

When to Use

Use this skill when:

  • Designing or implementing crypto engineer solutions
  • Reviewing or improving existing crypto engineer approaches
  • Making architectural or implementation decisions about crypto engineer
  • Learning crypto engineer patterns and best practices
  • Troubleshooting crypto engineer-related issues

Do NOT use this skill when:

  • The question is about a fundamentally different technology domain
  • A more specific sibling skill covers the exact topic needed
  • The user needs a complete hands-on tutorial rather than expert guidance

Output Format

markdown
# Crypto Engineer Analysis

## Context Assessment
[Situation summary and constraints]

## Recommended Approach
[Primary recommendation with rationale]

## Implementation Steps
1. [Step with specific details]
2. [Step with specific details]
3. [Step with specific details]

## Trade-offs and Considerations
- [Key trade-off 1]
- [Key trade-off 2]

## Next Steps
- [Immediate action item]
- [Follow-up action item]

Example

Input: "Help me implement crypto engineer for a medium-scale production application"

Output: A structured analysis covering current state assessment, recommended crypto engineer approach with specific patterns, implementation roadmap with milestones, and risk mitigation strategies tailored to the application scale and constraints.

Edge Cases

  • Legacy system integration: When crypto engineer must coexist with legacy approaches, provide a gradual migration path rather than a complete rewrite
  • Scale mismatch: When the solution complexity exceeds the project scale, recommend a simpler approach and note when to revisit
  • Team skill gaps: When the team lacks experience with the recommended approach, include learning resources and simpler alternatives
  • Conflicting requirements: When constraints conflict (e.g., performance vs. maintainability), explicitly state the trade-off and recommend based on stated priorities

© FerroxLabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in src/process/resources/skills-library/bodies/skills/security/crypto-engineer of FerroxLabs/wayland.

Open the folder on GitHubat commit 4c030c7

Compare with similar skills

Crypto Engineer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Crypto Engineer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Crypto Engineer this skillFerroxLabs/wayland608—~4kAutomated safety check: PassApache-2.0
Bom Explorecdxgen/cdxgen1.1k—~1.2kAutomated safety check: PassApache-2.0
Webcrypt MCPputervision/state-memory-mcp111—~847Automated safety check: PassMIT
Crypto Analysishypnguyen1209/offensive-claude386—~2.2kAutomated safety check: PassMIT
Security Reviewvalory-xyz/open-autonomy129—~11kAutomated safety check: NotesApache-2.0
Hashcat Password Recovery WorkflowAgentSecOps/SecOpsAgentKit2191 repos~3.3kAutomated safety check: NotesCustom licence

Similar skills

  • Bom Explore

    cdxgen/cdxgen

    Explores and triages a CycloneDX BOM interactively with the cdxi REPL, using built-in commands for dependency trees, licenses, services, cryptographic assets, audit findings, evidence occurrences…

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Webcrypt MCP

    putervision/state-memory-mcp

    Teaches the agent to use the WebCrypt MCP server for AES-256-GCM symmetric encryption, RSA-4096 hybrid encryption, key generation, digital signatures, hashing, and post-quantum cryptography.

    111 GitHub stars~847 tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Crypto Analysis

    hypnguyen1209/offensive-claude

    A skill your agent uses when assessing cryptography — TLS/PKI auditing, RSA/ECC key attacks, ECDSA nonce lattice recovery, symmetric/AEAD misuse, JWT/JOSE forgery, hash cracking, post-quantum…

    386 GitHub stars~2.2k tokensUpdated 10 days ago
    SecurityAuto-check passed
  • Security Review

    valory-xyz/open-autonomy

    Security review of an open-autonomy agent service — cryptographic key handling, dynamic code execution, ABCI authentication and replay, secret exposure, dependency supply chain, and deployment…

    129 GitHub stars~11k tokensUpdated 23 days ago
    SecurityAuto-check: notes
  • Hashcat Password Recovery Workflow

    AgentSecOps/SecOpsAgentKit

    Guides authorized password-hash recovery with hashcat for security audits, forensic cases and policy testing, starting with an explicit authorization check before any cracking runs.

    219 GitHub starsUsed in 1 repo~3.3k tokens
    SecurityAuto-check: notes
  • Altllm Portal Auth

    internet-court/internet-court-skill

    A skill your agent uses when the user asks to log in or out with a wallet session, fetch a wallet sign-in challenge, verify an externally signed challenge, or troubleshoot AltLLM Portal wallet login…

    6.4k GitHub starsUsed in 1 repo~632 tokens
    SecurityAuto-check passed

More from FerroxLabs/wayland

All 1,194 skills in this repo
  • Star Office Helper

    FerroxLabs/wayland

    Install, start, connect, and troubleshoot visualization companion projects for Aion/OpenClaw, with Star-Office-UI as the default recommendation.

    608 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check: notes
  • Openclaw Setup

    FerroxLabs/wayland

    OpenClaw usage expert: Helps you install, deploy, configure, and use OpenClaw personal AI assistant.

    608 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Tvcontrol Setup

    FerroxLabs/wayland

    Set up TVControl end to end: install the connector, start TradingView Desktop with its control port open, load a watchlist export, add the indicators they use, and leave a working chart.

    608 GitHub stars~5.7k tokensUpdated yesterday
    Auto-check passed
  • Ab Testing Specialist

    FerroxLabs/wayland

    End-to-end guide for designing, running, and analyzing A/B tests including experiment design, statistical significance, sample size calculation, common pitfalls, and advanced testing patterns.

    608 GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Academic Writer

    FerroxLabs/wayland

    Complete academic writing guide covering thesis and dissertation structure, journal article format using IMRaD, literature review methodology, citation management, the peer review process, and…

    608 GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Accessibility Auditor

    FerroxLabs/wayland

    Web accessibility expertise covering WCAG 2.2 conformance, audit methodology, ARIA patterns, keyboard navigation, screen reader testing, focus management, form accessibility, and automated vs manual…

    608 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Crypto Engineer

What does Crypto Engineer do?

Cryptography implementation expertise covering symmetric vs asymmetric encryption, password hashing (bcrypt, argon2), digital signatures, key management, TLS configuration, secure random generation…. Crypto Engineer is an agent skill from FerroxLabs/wayland. Cryptography implementation expertise covering symmetric vs asymmetric encryption, password hashing (bcrypt, argon2), digital signatures, key management, TLS configuration, secure random generation, common cryptographic pitfalls, and practical usage of libsodium and OpenSSL for building secure systems.

When should I use Crypto Engineer?

Crypto Engineer fits situations like: the user asks about crypto engineer; crypto engineer best practices; needs guidance on crypto engineer implementation; the user needs a different specialized skill.

How do I install Crypto Engineer in Claude Code?

Run `npx skills add FerroxLabs/wayland --skill crypto-engineer -a claude-code`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/security/crypto-engineer in FerroxLabs/wayland) into .claude/skills/crypto-engineer in your project. Claude Code loads it when a task matches its description.

How do I install Crypto Engineer in Codex?

Run `npx skills add FerroxLabs/wayland --skill crypto-engineer -a codex`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/security/crypto-engineer in FerroxLabs/wayland) into .agents/skills/crypto-engineer in your project. Codex loads it when a task matches its description.

Can I use Crypto Engineer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add FerroxLabs/wayland --skill crypto-engineer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/crypto-engineer, .gemini/skills/crypto-engineer, .github/skills/crypto-engineer and .opencode/skills/crypto-engineer in your project.

What does Crypto Engineer need to run?

Going by SKILL.md and its folder, Crypto Engineer needs the command-line tools its instructions call (openssl). Our summary lists: Python 3.

Does Crypto Engineer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Crypto Engineer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Crypto Engineer use?

Crypto Engineer is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Crypto Engineer use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Crypto Engineer?

Skills that share tags, products or a category with Crypto Engineer: Bom Explore (cdxgen/cdxgen, 1.1k stars), Webcrypt MCP (putervision/state-memory-mcp, 111 stars), Crypto Analysis (hypnguyen1209/offensive-claude, 386 stars) and Security Review (valory-xyz/open-autonomy, 129 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Crypto Engineer?

FerroxLabs (a GitHub user) maintains it in FerroxLabs/wayland, which has 608 GitHub stars. The repository holds 1,194 skills in this directory. The repository was last updated on October 6, 2026.

Source: FerroxLabs/wayland on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.